Petra Security

When Are Legitimate Apps Actually Malicious?

Uncovering malicious app registration using behavioral analysis.

Ed Torgas·August 7, 2026

Historically, attackers used only a short list of sketchy apps as persistence mechanisms during a compromise. While some people had real reasons to use them, security teams often adapted by simply blocking them outright.

Over the past several months, we've seen attackers adapt by leveraging popular apps that most people use legitimately.

If you understand both the behavior (the app registration and how the app is used) and the intent behind the behavior, these malicious app registrations can be valuable signals for detecting a compromise.

Combining an Unusual Login with Suspicious Activity

Below is a login for a compromise that we uncovered during a retrospective Petra Scan. The compromise occurred before Petra was onboarded.

In this case, the user, an Austin native, logged in from Phoenix for the first time ever. They also logged in from a brand new app, "officehome." Taken by itself, this is not particularly unusual. The travel was not impossible, and traveling users are more likely to use new apps.

Petra login history: an MFA challenge and a successful sign-in from Phoenix, AZ through a brand new app, "officehome," against a baseline of Austin, TX logins through Microsoft's own apps.

However, just after they logged in, they immediately signed the user up for Attio, a common CRM tool which can sync with email inboxes, and then quickly deleted both a "Your email has finished syncing with Attio" and a "Welcome to Attio!" email from the inbox.

Petra activity log: a successful login and an Attio app registration in the same second, then both the sync-complete and "Welcome to Attio!" emails read and moved to Deleted Items over the next two hours.

Analyzing Behavior around the Registration

On their own, none of these actions indicate a compromise. A traveling user simply logged in, signed up for a common SaaS tool, and then deleted a welcome email and an onboarding email. Maybe this user just likes to keep a tidy inbox!

However, when you combine the unusual login, the app registration, and the email deletions, what may have seemed like a string of independently benign actions reveals a clearly compromised account.

Why Catching Malicious Apps Matters

Attackers commonly use these benign tools as the very first step of their attack after login. They know that this is their least likely to be detected tactic, so they lead with it. Then, they move on to more obviously malicious actions, like sending fraudulent emails.

In the case above, the attacker sent out 600+ fraudulent emails a few hours after they installed Attio.

If the attack had been detected when Attio was installed, the attack would've stopped there, avoiding significant reputational harm and potential financial harm.

Petra blast radius: across just under two days of access, the attacker read 3,932 emails and 2 documents, sent 607 emails, modified 7 emails and 2 documents, and deleted 48 emails.

Even if the app wasn't used to detect the compromise, it's still important to flag as part of the attack. Some tools (like Attio) sync with email mailboxes even after the compromise is locked out. If your detection flagged on a malicious inbox rule or a fraudulent email send, you might not have uncovered that Attio was another layer of the attack and failed to remediate it. The app could remain installed, stealing emails long after the password is reset and the session is revoked.

Takeaways:

  • Attackers use legitimate apps maliciously.
  • The malicious intent can be detected quickly through behavioral analysis.

See what's in your last six months of logs.

Get insurance-grade forensics on the last 6 months of your M365 logs. Setup takes 5 minutes with results in 48 hours.